1 results (0.003 seconds)
CVSS: 9.8EPSS: 0%CPEs: 5EXPL: 0

CVE-2019-3773 – Spring Web Services XML External Entity Injection (XXE)
https://notcve.org/view.php?id=CVE-2019-3773
18 Jan 2019 — Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources. Spring Web Services, en sus versiones 2.4.3, 3.0.4 y anteriores no soportadas de los tres proyectos, era susceptible a inyecciones XEE (XML External Entity) cuando recibía datos XML de fuentes no fiables. This release of Red Hat Fuse 7.8.0 serves as a replacement for Red Hat Fuse 7.7, and includes bug fixes a... • https://pivotal.io/security/cve-2019-3773 • CWE-20: Improper Input Validation CWE-611: Improper Restriction of XML External Entity Reference •